Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Naver RUA (Real User Analytics) is a cookie based analytics and advertising measurement tag from Naver, the leading South Korean search platform. For European websites it sets persistent identifiers, tracks visitor behaviour and feeds Naver advertising. Because it relies on non essential cookies and sends data to South Korea, it requires prior consent under the ePrivacy rules and a valid GDPR legal basis. South Korea holds an EU adequacy decision, which simplifies the international transfer analysis but does not remove the consent obligation.
Naver RUA, short for Real User Analytics, is a measurement and analytics tag provided by Naver, the dominant search and web platform in South Korea. European organisations usually deploy it when they target Korean audiences or run campaigns through Naver advertising. The tag records how visitors browse a site, which pages they view and how they convert, and it often ties that behaviour back to Naver advertising performance. Because it is a third party tag loaded from Naver domains, it brings the site operator into a relationship with a processor located outside the European Economic Area.
Naver RUA relies on cookies set on Naver domains, including identifiers such as NID_AUT and NID_SES that persist across sessions, alongside advertising cookies like npic. Through these it collects device and browser information, page interactions, referral data and a persistent visitor identifier that allows behaviour to be linked over time. When combined with Naver advertising, the data can support audience measurement and campaign attribution. None of these cookies are strictly necessary to deliver the website, which means they fall squarely within the category of non essential trackers under the ePrivacy rules.
Two layers of European law apply at the same time. Article 5(3) of the ePrivacy Directive governs the act of reading and writing cookies on the user device and requires prior consent for anything that is not strictly necessary. The GDPR then governs the personal data that flows from those identifiers, since a persistent visitor identifier is personal data. Naver therefore acts as a processor or a separate controller depending on the configuration, and the site operator must have a written arrangement, a clear lawful basis and transparent information for users before the tag fires.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Naver RUA uses analytics and advertising cookies, valid prior consent is required before the tag loads. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. In practice this means the tag should be blocked by your consent management platform until the visitor opts in, and a record of the choice should be kept. Pre ticked boxes, implied consent from continued browsing and cookie walls that leave no genuine choice will not satisfy European regulators.
Naver processes data on infrastructure in South Korea, so using the tag involves a transfer of personal data outside the European Economic Area. The picture here is more favourable than for many destinations, because the European Commission adopted an adequacy decision for South Korea in December 2021 covering commercial operators under the PIPA. Transfers to a covered recipient can therefore rely on that decision without additional Standard Contractual Clauses. You should still confirm that Naver as the specific recipient falls within the material scope of the decision and document that assessment.
Start by mapping every Naver cookie and identifier in your records of processing, then route the tag through a consent management platform so it stays dormant until the visitor accepts. Update your cookie policy and privacy notice to name Naver, describe the analytics and advertising purposes and explain the transfer to South Korea and the adequacy decision that supports it. Configure a sensible retention period, offer a simple way to withdraw consent, and review the setup whenever Naver changes its cookies or you add advertising features. Keep evidence of consent and of your transfer assessment so you can demonstrate accountability on request.
Websites using Naver RUA must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is not always mandatory for Naver RUA, but it is recommended where the tag is combined with advertising audiences or large scale behavioural tracking. Document the categories of data collected, the persistent identifiers used, the retention periods and the transfer to South Korea. Record the reliance on the 2021 adequacy decision and confirm the recipient falls within its commercial scope. Assess whether profiling reaches a scale that triggers a mandatory assessment under GDPR article 35.
Sample consent text
We use Naver RUA analytics and advertising cookies to measure how visitors use this site and to support advertising. These cookies are only set after you accept them and may transfer data to Naver in South Korea, a country recognised by the European Commission as offering an adequate level of protection. You can accept or refuse them and change your choice at any time.
Third-party domains contacted
naver.comnid.naver.comwcs.naver.netssl.pstatic.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| NID_AUT | analytics | persistent (up to 1 year) | Naver authentication and analytics identifier used to recognise the visitor and link behaviour across sessions. |
| NID_SES | analytics | session | Maintains the visitor session state for Naver services and analytics measurement. |
| npic | advertising | persistent (up to 1 year) | Supports Naver advertising measurement and audience attribution. |
| nx_ssl | functional | persistent | Helps deliver Naver content securely over an encrypted connection. |
Naver RUA collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Naver RUA sets cookies on Naver domains, including persistent identifiers such as NID_AUT and the session cookie NID_SES, plus advertising cookies like npic. These are used for analytics and advertising measurement and are not strictly necessary, so they require consent.
Yes. Because the tag relies on analytics and advertising cookies that are not strictly necessary, you must obtain prior, freely given consent before it loads. The tag should remain blocked until the visitor opts in.
The lawful basis is the visitor consent under GDPR article 6(1)(a), combined with the prior consent required by article 5(3) of the ePrivacy Directive for storing and reading the cookies. Legitimate interest is not an appropriate basis for these advertising and analytics trackers.
Yes. Data is processed on Naver infrastructure in South Korea. South Korea benefits from a European Commission adequacy decision adopted in December 2021 for commercial operators under the PIPA, so the transfer can rely on that decision without extra Standard Contractual Clauses, provided the recipient is within its scope.
A data protection impact assessment is not always mandatory, but it is recommended where Naver RUA feeds advertising audiences or large scale behavioural tracking. Document the data, identifiers, retention and the transfer to Korea, and assess whether the profiling reaches a scale that triggers a mandatory assessment under article 35.
Block the tag through a consent management platform until the visitor accepts, name Naver in your cookie policy and privacy notice, and explain the analytics, advertising and Korea transfer. Keep proof of consent, set a sensible retention period and offer an easy way to withdraw consent.
If you do not target Korean audiences, privacy first analytics tools that keep data in the European Economic Area or offer a cookieless mode can reduce your compliance burden. For Korean campaigns, Naver remains the main option, so focus on consent gating and clear transfer disclosure.
List each Naver cookie with its purpose and duration, state that data is transferred to Naver in South Korea under the EU adequacy decision, and link to your consent settings. Review the entry whenever Naver changes its cookies or you add advertising features.